calcom cal.diy是calcom的Web中间件。 calcom cal.diy 5.9.9之前版本存在代码注入漏洞,该漏洞源于捆绑的Next.js版本中React Server Components (RSC)请求处理反序列化攻击者控制的输入,可能导致未经身份验证的远程攻击者发送特制RSC请求,在服务端处理过程中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58354 | 9.9 CRITICAL | cal.com Repository Takeover via pull_request_target Workflow |
| CVE-2024-58355 | 8.9 HIGH | Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
| CVE-2024-58353 | 8.9 HIGH | Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
No comments yet